Skip to content
Noroxi

OpenClaw records

577 published records for vendor openclaw.

All records

577 records
  • OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket conne

    HighCVSS 8.8Proof of conceptEPSS 24%

    openclaw · openclawFeb 1, 2026

  • A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Si

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    openclaw · openclawMar 11, 2026

  • Authenticated Command Injection in OpenClaw Docker Execution via PATH Environment Variable

    HighCVSS 8.8No exploitEPSS 5%

    openclaw · openclawFeb 2, 2026

  • OpenClaw < 2026.3.13 - Remote Command Injection via Unsanitized iMessage Attachment Paths in SCP

    CriticalCVSS 9.2No exploitEPSS 3%

    openclaw · openclawMar 31, 2026

  • OpenClaw Nextcloud Talk < 2026.2.6 - Allowlist Bypass via actor.name Display Name Spoofing

    CriticalCVSS 9.3No exploitEPSS 1%

    openclaw · openclawMar 5, 2026

  • OpenClaw < 2026.2.14 - Remote Code Execution via Node Invoke Approval Bypass

    CriticalCVSS 9.4Proof of conceptEPSS 1%

    openclaw · openclawMar 5, 2026

  • OpenClaw < 2026.3.11 - Privilege Escalation via Unvalidated Scope in device.token.rotate

    CriticalCVSS 9.4No exploitEPSS 1%

    openclaw · openclawMar 29, 2026

  • OpenClaw < 2026.3.13 - Bootstrap Setup Code Replay via Device Pairing

    CriticalCVSS 9.3No exploitEPSS 1%

    openclaw · openclawMar 29, 2026

  • OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections

    CriticalCVSS 9.4No exploitEPSS 1%

    openclaw · openclawMar 20, 2026

  • OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approval

    CriticalCVSS 9.4Proof of conceptEPSS 1%

    openclaw · openclawMar 31, 2026

  • OpenClaw - Sandbox Network Isolation Bypass via docker.network=container Parameter

    CriticalCVSS 9.3No exploitEPSS 0%

    openclaw · openclawMar 19, 2026

  • OpenClaw < 2026.3.11 - Approval Bypass via Unrecognized Script Runners

    CriticalCVSS 9.4No exploitEPSS 0%

    openclaw · openclawMar 29, 2026

  • OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events

    CriticalCVSS 9.3No exploitEPSS 0%

    openclaw · openclawMay 5, 2026

  • OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Subagent Control Surface

    CriticalCVSS 9.3No exploitEPSS 0%

    openclaw · openclawMar 29, 2026

  • OpenClaw < 2026.4.15 - Authentication Bypass in Feishu Webhook and Card-Action Validation

    CriticalCVSS 9.2No exploitEPSS 1%

    openclaw · openclawMay 6, 2026

  • OpenClaw < 2026.2.1 - Inbound Allowlist Policy Bypass in voice-call Extension via Empty Caller ID and Suffix Matching

    CriticalCVSS 9.2No exploitEPSS 1%

    openclaw · openclawMar 5, 2026

  • OpenClaw < 2026.2.2 - Exec Allowlist Bypass via Command Substitution in Double Quotes

    CriticalCVSS 9.2No exploitEPSS 1%

    openclaw · openclawMar 5, 2026

  • OpenClaw < 2026.2.2 - Command Injection via cmd.exe Parsing Bypass in Allowlist Enforcement

    CriticalCVSS 9.2No exploitEPSS 1%

    openclaw · openclawMar 5, 2026

  • OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolution

    CriticalCVSS 9.2No exploitEPSS 1%

    openclaw · openclawMay 6, 2026

  • OpenClaw 2026.2.21 < 2026.4.10 - Authentication Bypass in Sandbox noVNC Helper Route

    CriticalCVSS 9.2No exploitEPSS 1%

    openclaw · openclawMay 6, 2026

  • OpenClaw 2026.4.7 < 2026.4.14 - Privilege Escalation via Untrusted Webhook Wake Events

    CriticalCVSS 9.1No exploitEPSS 1%

    openclaw · openclawMay 5, 2026

  • OpenClaw < 2026.2.2 - Device Identity Check Bypass in Gateway WebSocket Connect Handshake

    CriticalCVSS 9.2No exploitEPSS 1%

    openclaw · openclawMar 5, 2026

  • OpenClaw 2026.3.7 < 2026.3.11 - Authorization Bypass in Plugin Subagent Routes via Synthetic Admin Scopes

    CriticalCVSS 9.2No exploitEPSS 1%

    openclaw · openclawMar 31, 2026

  • OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes

    CriticalCVSS 9.1No exploitEPSS 1%

    openclaw · openclawApr 28, 2026

  • OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation

    CriticalCVSS 9.0No exploitEPSS 1%

    openclaw · openclawApr 20, 2026